Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, read/write local files, and send data over the network, yet it declares no permissions. This is dangerous because it hides the real trust boundary from users and reviewers, especially since the skill explicitly requests, stores, and later uses an API key with a remote service.
